WordPress Trac: Ticket #18068: wp_list_bookmarks orderby broke in WP 3.1.4 (submiting per Per Andrew Nacin)https://core.trac.wordpress.org/ticket/18068
<p>
From: Andrew Nacin &lt;nacin@…&gt;
Date: July 11, 2011 11:16:52 AM EDT
To: Doug Foster &lt;doug@…&gt;
Subject: Re: if/how I should submit/track orderby bug in wp_list_bookmarks()?
</p>
<p>
Hi Doug,
</p>
<p>
Please submit a report here: <a class="ext-link" href="http://core.trac.wordpress.org"><span class="icon">​</span>http://core.trac.wordpress.org</a>. As soon as possible today would be great for our timelines.
</p>
<p>
Andrew
</p>
<p>
On Mon, Jul 11, 2011 at 11:12 AM, Doug Foster &lt;doug@…&gt; wrote:
Hi Andrew,
</p>
<p>
I wanted to check back and ask if/how I should submit this as a bug and track it. What would you suggest?
</p>
<p>
Thanks!
</p>
<p>
Doug
</p>
<p>
On Jul 1, 2011, at 12:38 PM, Doug Foster wrote:
</p>
<p>
Hi Andrew,
</p>
<p>
...
</p>
<p>
The Codex (<a class="ext-link" href="http://codex.wordpress.org/Function_Reference/wp_list_bookmarks"><span class="icon">​</span>http://codex.wordpress.org/Function_Reference/wp_list_bookmarks</a>) implies you would use "id" vs. the database field "link_id" as you mention, but in my searching I also found this kinda related issue (<a class="ext-link" href="http://wordpress.org/support/topic/problem-with-orderby-in-wp_list_bookmarks"><span class="icon">​</span>http://wordpress.org/support/topic/problem-with-orderby-in-wp_list_bookmarks</a>).
</p>
<p>
You're right about the approach I took or My Link Order takes, but if you want to order links (a very reasonable thing to do) it looks like it is a common practice, and the Codex implies it is (or should be) a workable option. I guess the real question is a clean way to do it, literally like a sort-order field. And a Codex page that matches the functionality.
</p>
<p>
I'll try using link_id and deleting all the links and then re-entering those. Bummer, for my site and the ones I support that's gonna take some time.
</p>
<p>
...
</p>
<p>
Doug
</p>
<p>
On Jul 1, 2011, at 12:07 PM, Andrew Nacin wrote:
</p>
<p>
Hi Doug,
</p>
<p>
We couldn't have predicted that one, that's for sure. Orderby options weren't removed as much as they were whitelisted. Nearly every field remains sortable, but notes is a text field, so we couldn't have expected anyone to be ordering by that. (In fact, ordering by MySQL TEXT fields is pretty much a no-no.)
</p>
<p>
orderby=id didn't appear to have ever worked, but orderby=link_id works fine.
</p>
<p>
My Link Order adds a new column to the database. Ugly. Unfortunately there's no easy way to fix that from our end. But I'll take a look.
</p>
<p>
Andrew
</p>
<p>
On Fri, Jul 1, 2011 at 12:00 PM, Doug Foster &lt;doug@…&gt; wrote:
Hi Andrew,
</p>
<p>
...
</p>
<p>
Upgrading from WP 3.1.3 to 3.1.4 broke the ability to sort links by notes using wp_list_bookmarks orderby=notes (I assume the same holds true for get_bookmarks too).
</p>
<p>
I found this post (<a class="ext-link" href="http://wordpress.org/support/topic/plugin-my-link-order-wordpress-update-broke-my-order"><span class="icon">​</span>http://wordpress.org/support/topic/plugin-my-link-order-wordpress-update-broke-my-order</a>).
</p>
<p>
Reading this (<a class="ext-link" href="http://permalink.gmane.org/gmane.comp.security.full-disclosure/80532"><span class="icon">​</span>http://permalink.gmane.org/gmane.comp.security.full-disclosure/80532</a>) makes me think some of the orderby options were removed to address this threat.
</p>
<p>
It does seem that (other than name) rating still works, but that appears to be the only one. For a while I thought it was just that you could not orderby any field with a varchar type, but it appears that even orderby=id (which is bigint(20) type) doesn't work.
</p>
<p>
So, if you have many links (like I do on <a class="ext-link" href="http://theideamechanic.com"><span class="icon">​</span>http://theideamechanic.com</a>) – and used to orderby=notes – you're left looking for a work around:
I could put a number in the name but that looks ugly and hacky
I could use rating but you're limited to 10 links (I have more in my "Getting Started" category
I could write a query to pull links direct from the database, but that kinda defeats the abstraction of having the wp_list_bookmarks template tag.
</p>
en-usWordPress Trachttps://core.trac.wordpress.org/chrome/site/your_project_logo.pnghttps://core.trac.wordpress.org/ticket/18068
Trac 1.0.1apurdamMon, 08 Aug 2011 05:25:55 GMTcc changedhttps://core.trac.wordpress.org/ticket/18068#comment:1
https://core.trac.wordpress.org/ticket/18068#comment:1
<ul>
<li><strong>cc</strong>
<em>apurdam</em> added
</li>
</ul>
<p>
Just wondering if this bug is going to get attention?<br />
</p>
<p>
It seems several users have been using links notes for arbitrary sorting of links when displaying, and that got broken in 3.1.4, perhaps in response to the security issue mentioned by Doug.
The mod was in <strong>get_bookmarks</strong> and effectively filters out notes from a small list of allowed sort options. Unfortunately this removes the ability for arbitrary sorting.
I see three options, but I'm not a WP boffin, so don't know all the ins and outs of the suggestions:<br />
1) restore the use of notes for orderby in get_bookmarks, maybe with some smarts to improve the security. This could be as simple as adding notes to the list of allowed fields when processing the orderby argument in get_bookmarks<br />
2) add new (numeric) sorting attribute to links and add some new functionality to get_bookmarks to allow sorting by this new attribute. (requires update of database version)<br />
3) expand the number of levels in link_rating (drop down list would no longer be practical).<br />
</p>
<p>
There are no real workarounds apart from using link_id, which makes arbitrary sorting tedious to the extreme, and is just as bad a double-use of a field as using link_notes.<br />
Doug, a quick and dirty fix (unofficial stab at option 1) is suggested by me at <a class="ext-link" href="http://wordpress.org/support/topic/wp-32-wp_list_bookmarks-orderbyid-not-working"><span class="icon">​</span>http://wordpress.org/support/topic/wp-32-wp_list_bookmarks-orderbyid-not-working</a> , but I haven't fully considered the security issue that you mentioned.
</p>
TicketnacinFri, 30 Sep 2011 17:03:47 GMThttps://core.trac.wordpress.org/ticket/18068#comment:2
https://core.trac.wordpress.org/ticket/18068#comment:2
<p>
In <a class="changeset" href="https://core.trac.wordpress.org/changeset/18840" title="Allow 'id' to work in get_bookmarks(). Add link_notes even though such ...">[18840]</a>:
</p>
<div class="message"><p>
Allow 'id' to work in get_bookmarks(). Add link_notes even though such sorting is a bad idea. see <a class="closed ticket" href="https://core.trac.wordpress.org/ticket/18068" title="defect (bug): wp_list_bookmarks orderby broke in WP 3.1.4 (submiting per Per Andrew ... (closed: fixed)">#18068</a> for 3.3.<br />
</p>
</div>
TicketnacinFri, 30 Sep 2011 17:04:02 GMTkeywords, milestone changedhttps://core.trac.wordpress.org/ticket/18068#comment:3
https://core.trac.wordpress.org/ticket/18068#comment:3
<ul>
<li><strong>keywords</strong>
<em>has-patch</em> added; <em>needs-patch</em> removed
</li>
<li><strong>milestone</strong>
changed from <em>Awaiting Review</em> to <em>3.2.2</em>
</li>
</ul>
TicketscribuSun, 09 Oct 2011 19:25:43 GMTdescription changedhttps://core.trac.wordpress.org/ticket/18068#comment:4
https://core.trac.wordpress.org/ticket/18068#comment:4
<ul>
<li><strong>description</strong>
modified (<a href="/ticket/18068?action=diff&amp;version=4">diff</a>)
</li>
</ul>
TicketryanFri, 28 Oct 2011 19:41:07 GMTstatus, milestone changed; resolution sethttps://core.trac.wordpress.org/ticket/18068#comment:5
https://core.trac.wordpress.org/ticket/18068#comment:5
<ul>
<li><strong>status</strong>
changed from <em>new</em> to <em>closed</em>
</li>
<li><strong>resolution</strong>
set to <em>fixed</em>
</li>
<li><strong>milestone</strong>
changed from <em>3.2.2</em> to <em>3.3</em>
</li>
</ul>
Ticket